Access Point Flooding Attack Prevention with Timeouts and Power-Save Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems are vulnerable to authentication, association, and reassociation flooding attacks due to the lack of clear definitions in the Protected Management Frames (PMF) standard, particularly when non-AP stations operate in power saving mode or are attacked by malicious entities.
Innovation Solution
Implementing an attack prevention method at the access point (AP) that includes generating an authentication response frame with a timeout interval and ignoring specific request frames during power saving mode to prevent resource occupation and maintain secure connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the access point frequently sends Security Association Query requests to check if non-AP STA is alive, then connection monitoring is improved, but vulnerability to authentication flooding attack increases
Solution Approach 1:
The patent applies preliminary action by establishing a timeout interval mechanism in advance that automatically prevents the AP from sending SA Query requests during the timeout period. This pre-configured protective measure ensures that even if authentication flooding attacks occur, the AP will not respond to authentication requests during the timeout window, thereby preventing resource exhaustion while maintaining connection monitoring capability when needed.
2Ease of operation
If the access point processes authentication requests from non-AP STA in power saving mode, then connection management is improved, but resource occupation by flooding attacks increases
Solution Approach 1:
The patent detects when a non-AP STA enters power saving mode and preliminarily establishes a state where the AP ignores subsequent authentication requests during this mode. This preliminary detection and state establishment prevents the AP from processing unnecessary authentication requests that would consume resources, while still allowing legitimate reassociation requests to be handled when the STA returns from power saving mode.
3Speed
If the access point sends authentication response frames without timeout control, then authentication speed is improved, but susceptibility to flooding attacks worsens
Solution Approach 1:
The patent implements periodic action by introducing timeout intervals between authentication response transmissions. Instead of continuously or frequently sending authentication responses, the AP sends responses according to a periodic timeout-based schedule. This reduces the frequency of authentication frame exchanges to acceptable levels while maintaining adequate authentication functionality, thereby reducing susceptibility to flooding attacks.
Data Source
AI summary
An attack prevention method includes: receiving an authentication request frame; and in response to receiving the authentication request frame, replying with an authentication response frame that is sent to a non-access-point (non-AP) station (STA), wherein the authentication request frame includes a timeout interval element that carries Authentication Comeback time. Another attack prevention method includes: ignoring each specific request frame that is received within a period in which a connected non-AP STA operates under a power saving mode, wherein each specific request frame includes one of an authentication request frame, an association request frame, and a reassociation request frame.


