Wireless intrusion prevention system and its operating method

The WIPS system addresses unauthorized access in wireless networks by monitoring and controlling terminals with random MAC addresses, improving network security by allowing only identified or approved devices to connect.

JP7857971B2Active Publication Date: 2026-05-13SECUI COM CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
SECUI COM CORP
Filing Date
2022-04-05
Publication Date
2026-05-13

AI Technical Summary

Technical Problem

Existing wireless networks face challenges in blocking unauthorized access by terminals with random MAC addresses, which can lead to network intrusions and security breaches, particularly in environments using IEEE 802.11 or IEEE 802.11w technologies.

Method used

A wireless intrusion prevention system (WIPS) that includes a sensing device to monitor wireless frames and a controller to analyze MAC addresses, determining terminals with random MAC addresses and controlling access based on blocking policies, such as blocking unauthorized terminals and allowing access only to identified or approved devices.

Benefits of technology

Effectively blocks unauthorized access by terminals with random MAC addresses, enhancing network security by preventing intrusions and ensuring only legitimate devices can connect to the wireless network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007857971000001
    Figure 0007857971000001
  • Figure 0007857971000002
    Figure 0007857971000002
  • Figure 0007857971000003
    Figure 0007857971000003
Patent Text Reader

Abstract

The present technology relates to an electronic device, and a wireless intrusion prevention system according to the present technology may include a sensing device and a controller. The sensing device may monitor wireless frames transmitted and received between an access point (AP) and multiple terminals via a wireless network, and generate frame analysis information based on the wireless frames. The controller may compare manufacturer identification information including an organizationally unique identifier (OUI) with a media access control (MAC) address of each terminal included in the frame analysis information, determine a target terminal having a random MAC address among the multiple terminals based on the comparison result, and control the target terminal's access to the access point based on a blocking policy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a wireless intrusion prevention system (WIPS) and an operation method thereof.

Background Art

[0002] With the rapid development and popularization of the Internet, the network environment has become increasingly large, and its form has become complex due to the simple and convenient network access provided by the Internet and various services. However, due to various forms of network attacks on the Internet, such as viruses, hacking, system intrusion, acquisition of system administrator rights, concealment of intrusion facts, and denial-of-service attacks, the Internet is always at risk of hacking, and the infringement on the Internet is increasing. Public institutions, social infrastructure facilities, and financial institutions are suffering from an increasingly large scale of damage and have a great influence. To solve such Internet security problems, the need for network security technologies such as virus countermeasures, firewalls, integrated security management, and intrusion detection systems has emerged.

[0003] A wireless network system for wireless Internet communication includes a wireless LAN access point (AP) and a wireless LAN terminal. The AP is installed and used with equipment called an access point device.

[0004] Recently, an integrated network system that uses both wired and wireless has been widely developed and applied. It is difficult to stably block harmful traffic accessed via wired, and it is even more difficult to stably block harmful traffic accessed via wireless. To solve this problem, a wireless intrusion prevention system (WIPS) has been developed. The WIPS is a system that detects and blocks wireless intrusions such as unauthorized ( rogue ) APs or DoS (Denial of Service) attacks through monitoring of the wireless section. [Overview of the project] [Problems that the invention aims to solve]

[0005] The problem that the present invention aims to solve is to provide a wireless intrusion prevention system and a method for operating it that blocks access by a terminal having a random MAC address when the terminal accesses the AP via a wireless network to which, for example, IEEE 802.11 technology or IEEE 802.11w technology is applied, in accordance with a blocking policy. [Means for solving the problem]

[0006] A wireless intrusion prevention system according to an embodiment of the present invention may include a sensing device and a controller. The sensing device can monitor wireless frames transmitted and received between an access point (AP) and multiple terminals via a wireless network and generate frame analysis information based on the wireless frames. The controller compares manufacturer identification information, including an organizationally unique identifier (OUI), with the MAC (Media Access Control) address of each terminal included in the frame analysis information, determines a target terminal with a random MAC address among the multiple terminals based on the comparison result, and controls the target terminal's access to the access point based on a blocking policy.

[0007] The operation method of a Wireless Intrusion Prevention System (WIPS) according to an embodiment of the present invention may include the steps of: receiving an access request to an access point from a target terminal among a plurality of terminals that send and receive wireless frames with the access point via a wireless network; determining whether the MAC address of the target terminal is a random MAC address or a unique MAC address based on the result of comparing manufacturer identification information including an Organizationally Unique Identifier (OUI) with the MAC (Media Access Control) address of the target terminal included in the wireless frame; and controlling the target terminal's access to the access point depending on whether the MAC address of the target terminal is a random MAC address. [Effects of the Invention]

[0008] According to an embodiment of the present invention, for example, when a terminal is connected to an AP via IEEE802, the connection can be terminated and access blocked depending on whether the terminal's MAC address is a random MAC address or not. [Brief explanation of the drawing]

[0009] [Figure 1] This is a block diagram showing the configuration of a wireless intrusion prevention system. [Figure 2] This flowchart shows how to block access to a wireless intrusion prevention system. [Figure 3] This diagram illustrates terminal access control in a wireless intrusion prevention system according to one embodiment. [Figure 4] This is a flowchart illustrating the operation of a wireless intrusion prevention system according to one embodiment. [Figure 5] This is a flowchart illustrating the operation of a wireless intrusion prevention system according to one embodiment. [Figure 6]This is a flowchart illustrating the operation of a wireless intrusion prevention system according to one embodiment. [Figure 7] This is a flowchart illustrating the operation of a wireless intrusion prevention system according to one embodiment. [Modes for carrying out the invention]

[0010] The specific structural or functional descriptions of embodiments of the concept of the present invention disclosed herein or in the application are merely illustrative for the purpose of illustrating embodiments of the concept of the present invention, and embodiments of the concept of the present invention can be carried out in a variety of forms and should not be interpreted as being limited to the embodiments described herein or in the application.

[0011] Figure 1 is a block diagram showing the configuration of a wireless intrusion prevention system.

[0012] Referring to Figure 1, the Wireless Intrusion Prevention System (WIPS) detects unauthorized access via wireless monitoring. rogue This system detects and blocks wireless intrusions such as AP (Access Point) or DoS (Denial of Service) attacks.

[0013] The general wireless networks described herein may include wireless networks to which IEEE 802.11 or IEEE 802.11w is applied. IEEE 802.11w is a modification of IEEE 802.11 that enhances the security of management frames. However, without limitation, embodiments of the present invention are applicable to wireless networks to which various security technologies are applied.

[0014] A wireless network system includes one or more Basic Service Sets (BSS), where a BSS represents a collection of devices that can successfully synchronize and communicate with one another. Typically, BSSs are divided into infrastructure BSSs and independent BSSs (IBSSs).

[0015] An access point (AP) is an individual device that provides access to a distribution system via a wireless medium for terminals associated with it. The term AP is used in a broad sense to include the concept of a PCP (Personal BSS Coordination Point), and can encompass all concepts such as a central controller, base station (BS), node-B, BTS (Base Transceiver System), or site controller. In this invention, an AP may also be referred to as a base wireless communication terminal, and the term base wireless communication terminal may be used in a broad sense to encompass all APs, base stations, eNBs (eNodeBs), and transmission points (TPs). Furthermore, a base wireless communication terminal may include various forms of wireless communication terminals that allocate and schedule medium resources in communication with multiple wireless communication terminals.

[0016] A station is any device that includes medium access control (MAC) and a physical layer interface to a wireless medium in accordance with the IEEE 802.11 standard, and in a broad sense, can include not only non-AP stations but also all access points (APs). In this specification, "station" refers to a non-AP station, but in some embodiments, it may be used as a term to refer to all non-AP stations and APs. A station for wireless communication includes a processor and a transmitter / receiver, and in some embodiments, may further include a user interface and a display unit. The processor can generate frames to be transmitted over the wireless network, process frames received over the wireless network, and perform various other processing to control the station. The transmitter / receiver is functionally connected to the processor and transmits and receives frames over the wireless network for the station. The station can transmit and receive frames with the AP over the wireless network.

[0017] In this embodiment, WIPS10 can compare manufacturer identification information, including an Organizationally Unique Identifier (OUI), with the MAC (Media Access Control) address of each terminal included in the wireless frame. Based on the comparison result, WIPS10 can determine a target terminal with a random MAC address from among multiple terminals and control the target terminal's access to the access point based on a blocking policy.

[0018] In one embodiment, the blocking policy may be a policy that blocks access to the access point of a target terminal having a random MAC address and permits access to the access point of a terminal having a unique MAC address among a plurality of terminals. This is to block the connection of a terminal having a random MAC address for which the user cannot be identified and prevent intrusion into the wireless network.

[0019] In one embodiment, the blocking policy may be a policy that blocks access to the access point of a target terminal having a random MAC address, blocks access to the access point of a terminal having a non-registered MAC address among terminals having unique MAC addresses, and permits access to the access point of a terminal having a registered MAC address. This is to permit connection only for terminals whose access has been authorized among terminals having unique MAC addresses for which the user can be identified and prevent intrusion into the wireless network. The registered MAC address may be the MAC address of a terminal pre-registered by an administrator.

[0020] In one embodiment, the blocking policy may be a policy that blocks access to the access point of a target terminal having a random MAC address that has not received approval from an administrator and permits access to the access point of a terminal that has received approval from the administrator. This is to permit access exceptionally even for a terminal having a random MAC address for which the user cannot be identified if it has obtained prior approval from the administrator.

[0021] In an embodiment, the WIPS 10 may include a sensing device 100 and a controller 200.

[0022] The sensing device 100 can monitor wireless frames transmitted and received between multiple terminals and access points, and transmit frame analysis information obtained by analyzing the monitored wireless frames to the controller 200. The frame analysis information may include the MAC address of the terminal or AP that transmitted the wireless frame, security settings, transmission speed, SSID, whether IEEE802.11a / b / g / n / ac / ax is supported, channel, RSSI, etc. The sensing device 100 can execute a block command to the AP or terminal based on the block command information received from the controller 200.

[0023] In this embodiment, the sensing device 100 may include a sensing module 110 and a communication module 120.

[0024] The sensing module 110 can generate a blocking message based on blocking command information received from the controller 200. The sensing module 110 can control the communication module 120 to transmit the generated blocking message to the target AP and terminal. The communication module 120 can transmit the blocking message to the target AP and terminal.

[0025] In this embodiment, the sensing module 110 may include a sensor receiving unit 111, a sensor analysis unit 112, and a sensor blocking unit 113.

[0026] The sensor receiver 111 can control the communication module 120 to monitor wireless frames on multiple channels.

[0027] The sensor analysis unit 112 can transmit frame analysis information, obtained by analyzing the received wireless frame as a result of monitoring, to the controller 200. The frame analysis information may include information about the AP or terminal that transmitted the wireless frame.

[0028] The sensor shut-off unit 113 can execute a shut-off command. The sensor shut-off unit 113 can generate a shut-off message based on the shut-off command information received from the controller 200.

[0029] For example, the sensor blocking unit 113 can generate blocking messages containing deauthentication frames in a typical wireless network where IEEE 802.11 is applied. The sensor blocking unit 113 can generate blocking messages containing jamming signals and spoofed packets in a secure wireless network where IEEE 802.11w is applied.

[0030] The sensor blocking unit 113 can control the communication module 120 to transmit the generated blocking message to the AP and terminal that sent and received the wireless frame. In this case, the sensor blocking unit 113 can set the address to which the blocking message is sent to the AP's BSSID and the address to which it is received to the terminal's MAC address. Alternatively, the sensor blocking unit 113 can set the address to which the blocking message is sent to the terminal's MAC address and the address to which it is received to the AP's BSSID. Upon receiving the blocking message transmitted from the communication module 120, the AP and terminal can determine that the other has transmitted a blocking message indicating the termination of the connection and can cancel each other's access.

[0031] The controller 200 can compare frame analysis information received from the sensing device 100 with database-stored signature information to determine whether the terminal or AP is unauthorized or malfunctioning. The signature information may include previously collected wireless frame information, blocking policies, or blocking target lists. If the terminal or AP is unauthorized or malfunctioning, the controller 200 can either automatically block it according to the blocking policy or generate an alarm to allow the administrator to manually block it.

[0032] In this embodiment, the controller 200 can determine which AP or terminal to block based on the blocking policy and frame analysis information.

[0033] The controller 200 can compare the manufacturer identification information with the MAC address of each terminal included in the frame analysis information. The manufacturer identification information may include a manufacturer-specific identifier registered with the IEEE. Based on the comparison results, the controller 200 can determine which terminals have a random MAC address and which have a unique MAC address from among the multiple terminals.

[0034] Specifically, the controller 200 can determine whether a terminal's MAC address is a random MAC address based on whether the upper 24 bits of the terminal's MAC address are included in the manufacturer's unique identifier. If the upper 24 bits of the terminal's MAC address are included in the manufacturer's unique identifier, the controller 200 can determine that the terminal's MAC address is a unique MAC address. If the upper 24 bits of the terminal's MAC address are different from the manufacturer's unique identifier, the sensing module 110 can determine that the terminal's MAC address is a random MAC address.

[0035] Blocking policies can be configured in various ways depending on the wireless network environment.

[0036] In one embodiment, the blocking policy may block access to the access point from target terminals with random MAC addresses, while allowing access to the access point from terminals with unique MAC addresses among multiple terminals. This is to prevent intrusion into the wireless network by blocking connections from terminals with random MAC addresses that cannot identify the user.

[0037] In one embodiment, the blocking policy may block access to the access point from target terminals with random MAC addresses, block access to the access point from terminals with unique MAC addresses that have unregistered MAC addresses, and allow access to the access point from terminals with registered MAC addresses. This is to prevent intrusion into the wireless network by allowing connections only from terminals with unique MAC addresses that can identify users and for which access is authorized. Registered MAC addresses may be MAC addresses of terminals that have been registered in advance by the administrator.

[0038] In one embodiment, the blocking policy may be a policy that blocks access to the access point from target devices with random MAC addresses that have not been approved by the administrator, while allowing access to the access point from devices that have been approved by the administrator. This is because even devices with random MAC addresses that cannot identify the user are exceptionally allowed access if they have received prior approval from the administrator.

[0039] The controller 200 can generate blocking command information and transmit the generated blocking command information to the sensing device 100. The blocking command information may include information about APs or terminals that are included in the blocking target list or that have been blocked due to a violation of the blocking policy.

[0040] In this embodiment, the controller 200 can block access from APs or terminals in various ways.

[0041] For example, the blocking method of the controller 200 may include AP blocking. In this case, when the controller 200 detects the BSSID of the AP to be blocked, it can block all terminals accessing the AP, rather than targeting a specific terminal.

[0042] As another example, the blocking method of the controller 200 may include terminal blocking. In this case, the controller 200 can block a terminal if it determines that it is an unauthorized terminal or if it detects that the terminal has been modulated to appear as an authorized terminal. When the MAC address of the terminal in question appears, the controller 200 can block all access to that AP.

[0043] As yet another example, the blocking method of the controller 200 may include specific AP-terminal blocking. In this case, the controller 200 can block connections when an authorized terminal is connected to an unauthorized AP, or when an unauthorized terminal is connected to an authorized AP. When the terminal MAC appears, the controller 200 may block access only to the specified AP and not intervene in access to other APs.

[0044] Figure 2 is a flowchart showing the method for blocking access to a wireless intrusion prevention system.

[0045] Referring to Figure 2, in step S201, the sensor receiving unit 111 can monitor wireless frames transmitted and received between the AP and multiple terminals via multiple channels.

[0046] In step S203, the sensor receiving unit 111 can call the sensor analysis unit 112 to analyze the received wireless frame.

[0047] In step S205, the sensor analysis unit 112 can analyze the wireless frame and generate frame analysis information. The frame analysis information may include the MAC address of the terminal or AP that transmitted the wireless frame, security settings, transmission speed, SSID, whether IEEE802.11a / b / g / n / ac / ax is enabled or disabled, channel, RSSI, etc.

[0048] In step S207, the sensor analysis unit 112 can provide frame analysis information to the controller 200.

[0049] In step S209, the controller 200 can add or update AP or terminal information that transmitted the wireless frame based on the frame analysis information.

[0050] In step S211, the controller 200 can determine whether the relevant AP or terminal violates the blocking policy based on the blocking policy.

[0051] In step S213, if the controller 200 determines that the AP or terminal in question is in violation of the blocking policy, it can generate blocking command information according to the policy setting.

[0052] In step S215, the controller 200 can transmit blocking command information to the sensor blocking unit 113. The blocking command information may include information about APs or terminals that are included in the blocking target list or that have been blocked due to a violation of the blocking policy.

[0053] In step S217, the sensor blocking unit 113 can execute a blocking command based on the received blocking command information. Specifically, the sensor blocking unit 113 can generate a blocking message based on the blocking command information. The sensor blocking unit 113 can control the communication module to transmit the blocking message to the target AP or terminal. The blocking message may include the aforementioned unauthenticated frames or jamming signals, or spoofed packets.

[0054] Figure 3 is a diagram illustrating terminal access control in a wireless intrusion prevention system according to one embodiment.

[0055] Referring to Figure 3, in step S301, terminal 30 can send a wireless frame containing an access request to AP20.

[0056] In step S303, the WIPS 10 can collect wireless frames transmitted between the AP 20 and the terminal 30.

[0057] In step S305, WIPS10 can determine whether the MAC address of terminal 30 included in the collected wireless frame is a random MAC address.

[0058] For example, WIPS10 can determine that terminal 30's MAC address is a unique MAC address if the upper 24 bits of its MAC address are included in the manufacturer's unique identifier, and determine that terminal 30's MAC address is a random MAC address if the upper 24 bits are different from the manufacturer's unique identifier. WIPS10 can obtain manufacturer identification information, including the manufacturer's unique identifier, from the IEEE.

[0059] In step S307, WIPS10 can determine if the MAC address of terminal 30 is a registered MAC address. A registered MAC address may be the MAC address of a terminal that the administrator has previously allowed to access the access point. In another embodiment, step S307 may be omitted.

[0060] In step S309, WIPS10 can determine whether terminal 30 is allowed to access AP20 according to the blocking policy.

[0061] In one embodiment, the blocking policy may block access to the access point from target terminals with random MAC addresses, while allowing access to the access point from terminals with unique MAC addresses among multiple terminals. This is to prevent intrusion into the wireless network by blocking connections from terminals with random MAC addresses that cannot identify the user.

[0062] In one embodiment, the blocking policy may block access to the access point from target terminals with random MAC addresses, block access to the access point from terminals with unique MAC addresses that have unregistered MAC addresses, and allow access to the access point from terminals with registered MAC addresses. This is to prevent intrusion into the wireless network by allowing connections only from terminals with unique MAC addresses that can identify users and for which access is authorized. Registered MAC addresses may be MAC addresses of terminals that have been registered in advance by the administrator.

[0063] In one embodiment, the blocking policy may be a policy that blocks access to the access point from target terminals with random MAC addresses that have not been approved by the administrator, while allowing access to the access point from terminals that have been approved by the administrator. This is because even terminals with random MAC addresses that cannot identify the user are exceptionally allowed access if approved by the administrator.

[0064] In step S311, WIPS10 can provide AP20 with access control information indicating whether terminal 30 is allowed to access AP20.

[0065] In step S313, AP20 can allow or block access from terminal 30 based on access control information.

[0066] Figure 4 is a flowchart illustrating the operation of a wireless intrusion prevention system according to one embodiment.

[0067] Referring to Figure 4, in step S401, the wireless intrusion prevention system can receive an Organizationally Unique Identifier (OUI) from the IEEE (Institute of Electrical and Electronics Engineers).

[0068] In step S403, the wireless intrusion prevention system can determine whether the MAC address of the terminal requesting access to the access point is a random MAC address based on the comparison result between the terminal's MAC address and the manufacturer's unique identifier.

[0069] In step S405, the wireless intrusion prevention system can determine whether to allow access to the terminal according to the blocking policy if the terminal's MAC address is a random MAC address.

[0070] Figure 5 is a flowchart illustrating the operation of a wireless intrusion prevention system according to one embodiment.

[0071] Referring to Figure 5, in step S501, the wireless intrusion prevention system can receive a wireless frame containing the MAC address of the terminal that requested access from the terminal.

[0072] In step S503, the wireless intrusion prevention system can determine whether the terminal's MAC address is a random MAC address. For example, if the terminal's MAC address matches the manufacturer's unique identifier, the wireless intrusion prevention system can determine that the terminal's MAC address is a unique MAC address; if the terminal's MAC address is different from the manufacturer's unique identifier, it can determine that the terminal's MAC address is a random MAC address.

[0073] The wireless intrusion prevention system proceeds to step S505 if, as a result of its determination, the terminal's MAC address is a random MAC address, and proceeds to step S507 if the terminal's MAC address is a unique MAC address.

[0074] In step S505, the wireless intrusion prevention system can block access to the access point from a terminal having a random MAC address.

[0075] In step S507, the wireless intrusion prevention system may allow access to the access point by a terminal having a unique MAC address.

[0076] According to the embodiment shown in Figure 5, access to the access point from a target terminal with a random MAC address can be blocked, while access to the access point from terminals with unique MAC addresses among multiple terminals can be permitted. This is to prevent intrusion into the wireless network by blocking connections from terminals with random MAC addresses that cannot identify the user.

[0077] Figure 6 is a flowchart illustrating the operation of a wireless intrusion prevention system according to one embodiment.

[0078] Referring to Figure 6, in step S601, the wireless intrusion prevention system can receive a wireless frame containing the MAC address of the terminal that requested access from the terminal.

[0079] In step S603, the wireless intrusion prevention system can determine whether the terminal's MAC address is a random MAC address.

[0080] The wireless intrusion prevention system, based on its determination, proceeds to step S605 if the terminal's MAC address is a random MAC address, and proceeds to step S607 if the terminal's MAC address is a unique MAC address. It can receive wireless frames including [specific frames].

[0081] In step S605, the wireless intrusion prevention system can block access to the access point from a terminal having a random MAC address.

[0082] In step S607, the wireless intrusion prevention system can determine whether the terminal's MAC address is a registered MAC address. If the determination is that the terminal's MAC address is a registered MAC address, the system proceeds to step S609; otherwise, it proceeds to step S605. A registered MAC address may be the MAC address of a terminal that the administrator has previously allowed to access the access point.

[0083] In step S609, the wireless intrusion prevention system may allow access to the access point by a terminal having a registered MAC address.

[0084] According to the embodiment in Figure 6, access to the access point by target terminals with random MAC addresses can be blocked. Among terminals with unique MAC addresses, access to the access point by terminals with unregistered MAC addresses can be blocked, while access to the access point by terminals with registered MAC addresses can be allowed. This is to prevent intrusion into the wireless network by allowing connections only from terminals with unique MAC addresses that have been authorized by the administrator.

[0085] Figure 7 is a flowchart illustrating the operation of a wireless intrusion prevention system according to one embodiment.

[0086] Referring to Figure 7, in step S701, the wireless intrusion prevention system can receive a wireless frame containing the MAC address of the terminal that requested access to the access point from the terminal.

[0087] In step S703, the wireless intrusion prevention system can determine whether the terminal's MAC address is a random MAC address. If the wireless intrusion prevention system determines that the terminal's MAC address is a random MAC address, it proceeds to step S705; if the terminal's MAC address is a unique MAC address, it proceeds to step S709.

[0088] In step S705, the wireless intrusion prevention system can determine whether the terminal is a terminal that has been pre-approved by the administrator based on the blocking policy. If the wireless intrusion prevention system determines that the terminal is a pre-approved terminal, it proceeds to step S709; otherwise, it proceeds to step S707.

[0089] In step S707, the wireless intrusion prevention system can block access to the access point from devices with random MAC addresses that have not been pre-approved by the administrator.

[0090] In step S709, the wireless intrusion prevention system may allow access to the access point by terminals that have a unique MAC address or a random MAC address, provided that the terminal has been pre-approved by the administrator.

[0091] According to the embodiment shown in Figure 7, among target terminals with random MAC addresses, access to the access point can be blocked for terminals that have not been approved by the administrator, while access to the access point can be permitted for terminals that have been pre-approved by the administrator. This is because even terminals with random MAC addresses that cannot identify the user are exceptionally allowed access if they have been pre-approved by the administrator.

Claims

1. A sensing device that monitors wireless frames transmitted and received between an access point (AP) and multiple terminals via a wireless network, and generates frame analysis information based on the wireless frames, A controller that compares manufacturer identification information, including an Organisationally Unique Identifier (OUI), with the MAC (Media Access Control) address of each terminal included in the frame analysis information, determines, based on the comparison result, which terminals have a random MAC address and which have a unique MAC address among the multiple terminals, blocks access to the access point by the target terminals, and allows access to the access point by terminals with unique MAC addresses, The above controller is A Wireless Intrusion Prevention System (WIPS) characterized by determining that if the upper 24 bits of the MAC address contained in the above MAC address are included in the above manufacturer-specific identifier, the MAC address is determined to be a unique MAC address, and if the upper 24 bits of the MAC address are different from the above manufacturer-specific identifier, the MAC address is determined to be a random MAC address.

2. A sensing device that monitors wireless frames transmitted and received between an access point (AP) and multiple terminals via a wireless network, and generates frame analysis information based on the wireless frames, A controller that compares manufacturer identification information, including an Organisationally Unique Identifier (OUI), with the MAC (Media Access Control) address of each terminal included in the frame analysis information, determines, based on the comparison result, which terminals have a random MAC address and which have a unique MAC address among the multiple terminals, blocks access to the access point by the target terminals, and allows access to the access point by terminals with unique MAC addresses, The above controller is A wireless intrusion prevention system characterized by lifting the blockage of access to the access point for terminals among the target terminals that have been pre-approved by the administrator.

3. The above controller is The wireless intrusion prevention system according to claim 1 or 2, characterized in that it obtains the above-mentioned manufacturer identification information from the IEEE (Institute of Electrical and Electronics Engineers).

4. The above controller is The wireless intrusion prevention system according to claim 1, characterized in that it allows access to the access point by a terminal having the above-mentioned unique MAC address depending on whether or not the above-mentioned unique MAC address is a registered MAC address.

5. The above wireless network is The wireless intrusion prevention system according to claim 1 or 2, characterized in that it includes a general wireless network to which IEEE 802.11 applies and a secure wireless network to which IEEE 802.11w applies.

6. The above frame analysis information is, The wireless intrusion prevention system according to claim 1 or 2, characterized in that it includes at least one of the following: the MAC address of the terminal that sent and received the above wireless frame, the SSID (Service Set Identifier) ​​of the access point, security settings, transmission speed, IEEE 802.11 version, channel information, and RSSI (Received Signal Strength Indication).

7. The process involves receiving an access request to the access point from a target terminal among multiple terminals that send and receive wireless frames with the access point via a wireless network, and A step of determining whether the MAC address of the target terminal is a random MAC address or a unique MAC address based on the result of comparing manufacturer identification information, including the Manufacturer Uniquely Identifier (OUI), with the MAC (Media Access Control) address of the target terminal included in the wireless frame, The process includes the steps of: blocking the target terminal's access to the access point if the target terminal's MAC address is the random MAC address; and allowing the target terminal's access to the access point if the target terminal's MAC address is the unique MAC address. The steps to make the above decision are: A method for operating a Wireless Intrusion Prevention System (WIPS), characterized in that if the upper 24 bits of the MAC address contained in the above MAC address are included in the above manufacturer-specific identifier, the MAC address is determined to be a unique MAC address, and if the upper 24 bits of the MAC address are different from the above manufacturer-specific identifier, the MAC address is determined to be a random MAC address.

8. A step of receiving an access request to the access point from a target terminal among a plurality of terminals that transmit and receive wireless frames with an access point via a wireless network, A step of determining whether the MAC address of the target terminal is a random MAC address or a unique MAC address based on the result of comparing manufacturer identification information, including the Manufacturer Uniquely Identifier (OUI), with the MAC (Media Access Control) address of the target terminal included in the wireless frame, The process includes the steps of: blocking the target terminal's access to the access point if the target terminal's MAC address is the random MAC address; and allowing the target terminal's access to the access point if the target terminal's MAC address is the unique MAC address. If the MAC address of the target terminal is the random MAC address, the step of blocking the target terminal's access to the access point is as follows: A method for operating a wireless intrusion prevention system, characterized by releasing the blockage of the target terminal's access to the access point depending on whether or not the target terminal has been pre-approved by the administrator.

9. If the MAC address of the target terminal is the unique MAC address, the step of allowing the target terminal to access the access point is as follows: The method for operating the wireless intrusion prevention system according to claim 7, characterized in that access by the target terminal to the access point is permitted depending on whether or not the above-mentioned unique MAC address is a registered MAC address.

10. The method for operating a wireless intrusion prevention system according to claim 7 or 8, further comprising the step of obtaining the above-mentioned manufacturer identification information from the IEEE (Institute of Electrical and Electronics Engineers).

11. The steps include generating a blocking message to block the target terminal's access to the access point, A method for operating a wireless intrusion prevention system according to claim 7 or 8, further comprising the step of transmitting the blocking message, which includes an unauthenticated frame or includes a jamming signal and a spoofed packet, to the target terminal.

12. The above wireless network is A method for operating a wireless intrusion prevention system according to claim 7 or 8, characterized in that it includes a general wireless network to which IEEE 802.11 applies and a secure wireless network to which IEEE 802.11w applies.